Summary

Adobe has released a security update for Adobe Connect. This update resolves a critical Server-Side Request Forgery (SSRF) vulnerability (CVE-2017-11291) that could be abused to bypass network access controls. This update also resolves three input validation vulnerabilities rated Important (CVE-2017-11287, CVE-2017-11288, CVE-2017-11289) that could be used in reflected cross-site scripting attacks. Finally, this update includes a feature that enables Connect administrators to protect users from UI redressing (or clickjacking) attacks (CVE-2017-11290).

Affected product versions

Product

Version

Platform

Adobe Connect

9.6.2 and earlier

All

Solution

Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version: